Back to skill

Security audit

create-subagent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain Markdown guide for creating persistent subagent prompt files, with no executable code or hidden install behavior.

Before installing, understand that this skill helps create persistent subagent prompt files. Prefer project-level agents when the behavior is codebase-specific, review generated descriptions so proactive triggers are not too broad, and be cautious with examples that use external tools such as BigQuery by adding explicit scope and authorization rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Use immediately after writing or modifying code" is expansive and likely to match routine development activity very frequently. It lacks exclusions or constraints that would help prevent unintended delegation on trivial edits.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance to include "use proactively" promotes ambiguous activation conditions without defining boundaries or exclusions. This can cause subagents to be invoked in many ordinary situations rather than only in narrowly specified contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction "Use proactively when encountering any issues" is vague because "any issues" is not bounded and could include minor or unrelated problems. Without clearer criteria, the trigger may collide with many normal conversational contexts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

The data-scientist example explicitly instructs use of BigQuery command-line tools when appropriate, which can operate against real user credentials and external datasets from an agent prompt. In the context of a skill for creating reusable subagents, this increases the chance that a generated subagent will perform external, potentially stateful actions or access sensitive data without sufficient approval, scoping, or guardrails.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
When invoked:
1. Understand the data analysis requirement
2. Write efficient SQL queries
3. Use BigQuery command line tools (bq) when appropriate
4. Analyze and summarize results
5. Present findings clearly

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase "Use proactively for data analysis tasks and queries" is somewhat general and does not specify what kinds of requests qualify or where the boundaries are. This increases the chance of unintended invocation for routine mentions of data or queries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.